Back to Feed
Nation-stateOct 3, 2026

MI5 Says China’s MSS Funded Research Involving 100+ U.K.-Linked Academics

MI5 warns over 100 UK academics aided China's MSS in research for espionage.

Summary

The UK's MI5 has issued an alert warning that over 100 academics linked to the UK have assisted China's Ministry of State Security (MSS) in research projects. These projects, funded by the MSS through a front company called the China General Technology Research Institute (CGTRI), focus on areas like AI, cybersecurity, and steganography, directly enhancing China's espionage capabilities. Some academics may be unaware of CGTRI's true purpose, and institutions are urged to review collaborations and funding sources to avoid potential prosecution under the National Security Act 2023.

Full text

MI5 Says China’s MSS Funded Research Involving 100+ U.K.-Linked Academics Ravie LakshmananOct 03, 2026Cyber Espionage / Artificial Intelligence The U.K.'s domestic intelligence and security agency has warned that more than 100 academics have helped China boost its intelligence gathering efforts on behalf of Beijing's state security service. In a "Security Service Espionage Alert" issued on September 30, 2026, MI5 said the "primary purpose of the China General Technology Research Institute (CGTRI) 中国通用技术研究院 is to fund research that directly improves Chinese Ministry of State Security (MSS) technical capability for espionage." CGTRI, also known as the China Academy of General Technology (CAGT), is assessed to be a front company for MSS. The body, per MI5, funds academic research in China on topics including artificial intelligence (AI), cybersecurity, covert communications systems, and steganography. More than 100 U.K.-linked academics have contributed to research projects funded by MSS via CGTRI, the alert read. In some cases, the individuals may not be aware that CGTRI is providing monetary backing to the Chinese research project they are contributing to. "This activity supports MSS espionage, which poses a threat to U.K. national security," the unprecedented alert said. U.K. academic institutions are being urged to immediately review any ongoing or planned collaboration with CGTRI, and trace the funding source when conducting research collaborations with Chinese institutions to ensure that the entity is not involved. The alert has also cautioned that institutions, staff, and researchers continuing to collaborate could be prosecuted under the National Security Act 2023 for providing material assistance to a foreign intelligence service in carrying out U.K.-related activities. Responding to the alert, the Chinese embassy in the U.K. called the accusations "imaginary and purely fabricated." "We firmly oppose such baseless allegations and have lodged solemn representations with the U.K. side," an embassy spokesperson added. "Exchanges and collaboration between U.K. universities and China have always been conducted on a voluntary basis and in compliance with laws and regulations. Such exchanges and collaboration are mutually beneficial." "We urge the U.K. intelligence authorities to stop spreading falsehoods and stop undermining educational exchanges and research cooperation between China and the U.K." In August 2025, a report from the U.K.-China Transparency (UKCT) think tank revealed that Chinese students at U.K. universities are being forced to spy on their classmates in an attempt to suppress discussing issues that are sensitive to the Chinese government, an allegation the Chinese embassy has called "groundless and absurd." "CGTRI [...] has identifiable staffing overlaps with China's University of International Relations, widely known to be uniquely closely affiliated with China's Ministry of State Security," UKCT said. "CGTRI specialises in cybersecurity, signals intelligence, and a variety of AI-enabled tools for strategic national objectives." "These specialties include capabilities especially useful for conducting cyber-attacks of the kind that Chinese government agencies, including the MSS, have executed against U.K. targets, including companies, universities, and public services and infrastructure." Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  artificial intelligence, cyber espionage, Nation-State ⚡ Top Stories This Week Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions ThreatsDay: AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content OpenAI Agent Bypassed Australian Medicare Portal Controls to Access Non-Public Files A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers Researcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender Updates New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access Beyond ISO 27001: Building a Risk Program That Can Keep Up With AI Secrets Sprawl Is an Identity Problem That AI Just Made Impossible to Ignore ⭐ Featured Resources Validation Summit ’26: See How Pen Testing, Exposure Validation and BAS Work Together Red Teams: Learn How Attack Path Chaining Changes Automated Security Testing Turn Threat Intelligence Into Verified Risk With Threat-Led Penetration Testing Deploy Browser Security Monitoring in Minutes With a Single Header

Entities

MI5 (vendor)China's MSS (threat_actor)Artificial Intelligence (AI) (technology)cybersecurity (technology)